• 0 Posts
  • 1 Comment
Joined 3 years ago
cake
Cake day: June 12th, 2023

help-circle
  • I was going to build my system like that, but recently learned that host client isolation is not as strong as people make you believe.

    just a few weeks ago we learned that copy fail (security vulnerability) was on major distros for years until it was fixed, it would allow containers and VMS to infect the host system. Xz utils could also lead to a broken host client separation, as proxmox uses ssh for clustering and the like.

    So for really important stuff I am going to have a dedicated physical server or put it in cold storage altogether.

    That said, I am by no means an expert so feel free to correct me if I got something wrong.